Skip to main content
Trust Center

Salesforce Connected App Security Updates for Docusign Salesforce Integrations

08/09/2026

Docusign is updating all Docusign Salesforce integrations to align with Salesforce's latest connected app security requirements. This affects users of Docusign Apps Launcher, CLM/Gen for Salesforce, IAM for Sales, and Legacy eSignature for Salesforce. In compliance with these guidelines, we are implementing the following security controls:

  • Proof Key for Code Exchange (PKCE)

  • Refresh Token Rotation (RTR)

  • 30-day idle timeout for refresh tokens

  • Refresh token IP allowlists at the connected app level

Deployment across UAT and production environments is underway through early August 2026. Please check this page for updated enforcement timelines and contact Docusign Support if any issues are encountered.

Starting August 10, 2026, we recommend installing the latest Docusign Apps Launcher 8.6.1 package from AppExchange. This update ensures compliance with the new security protocols and streamlines reconnection. We have begun upgrading customer sandbox environments to version 8.6.1 and expect to complete this within one week.